.:[ packet storm ]:.
                             
the one stop shop
the one stop shop

 ///  File Name:glsa-200810-02.txt
Description:
Gentoo Linux Security Advisory GLSA 200810-02 - A search path vulnerability in Portage allows local attackers to execute commands with root privileges if emerge is called from untrusted directories. The Gentoo Security Team discovered that several ebuilds, such as sys-apps/portage, net-mail/fetchmail or app-editors/leo execute Python code using python -c, which includes the current working directory in Python's module search path. For several ebuild functions, Portage did not change the working directory from emerge's working directory. Versions less than 2.1.4.5 are affected.
Homepage:http://security.gentoo.org
File Size:3143
Related CVE(s):CVE-2008-4394
Last Modified:Oct 9 18:50:17 2008
MD5 Checksum:8b3fc0142e706b0bc424bf0de635b50a

 .:. Back